How We Protect
Your Data
Because of our Edge AI architecture, we hold dramatically less data than any comparable platform. This page explains exactly what we hold, why, and how you can control it.

The Edge AI Advantage
Unlike conventional safety platforms, RoseShield processes all behavioral data — browsing patterns, screen time, social signals — entirely on your device using our proprietary RoseShield Edge AI Engine.
This means raw personal data never reaches our servers. We cannot be compelled to hand over data we don't hold. We cannot be breached for data we never stored.
Raw browsing history
Message content
Photos or media
Location data
Keystroke logs
DHSI composite score
Anonymized safety signals
Account & billing info
Data We Hold — Full Register
Every category of data we process, with purpose and retention periods
Account Data
Contains PIIExamples: Email address, name, subscription status, account preferences
Purpose: Account management, billing, service delivery
DHSI Score Data
AnonymizedExamples: Composite score (0–100), anonymized pillar scores, trend direction
Purpose: Wellbeing dashboard, school/governance reporting
Safety Signal Data
AnonymizedExamples: Category flags (e.g., SCREEN_FATIGUE), delta values, confidence scores
Purpose: Safety alerts, trend analysis, policy reporting
Billing Data
Contains PIIExamples: Last 4 digits of card, billing address, transaction IDs
Purpose: Payment processing via Stripe
Device Identifiers
AnonymizedExamples: Anonymized device hash (not IMEI or MAC address)
Purpose: Multi-device management, license enforcement
Log Data
AnonymizedExamples: Anonymized IP prefix, browser type, app version, crash reports
Purpose: Security monitoring, debugging
Your Data Rights
Under GDPR, CCPA, and applicable privacy law, you have the following rights:
Right to Access
Request a full copy of all personal data we hold about you, delivered within 30 days.
Right to Rectification
Correct inaccurate or incomplete personal data. Updates take effect immediately.
Right to Erasure
Request deletion of all your personal data. We complete erasure within 30 days (usually 72 hours).
Right to Portability
Receive your data in a machine-readable format (JSON or CSV) for transfer to another provider.
Right to Object
Object to any processing of your data not strictly necessary for service delivery.
Right to Restrict
Request that we limit processing of your data while a complaint or query is being resolved.
International Data Transfers
How we handle cross-border data flows

United States
Legal Basis: Standard Contractual Clauses (SCCs)
Primary Infrastructure

European Union
Legal Basis: GDPR Art. 46 – SCCs
EU data residency available

United Kingdom
Legal Basis: UK IDTA (International Data Transfer Agreement)
UK data residency available

Australia
Legal Basis: Privacy Act 1988 – APP 8
ANZ data residency available
Security Measures
AES-256 encryption at rest
Zero-knowledge architecture for behavioral data
Annual third-party penetration testing
Automated anomaly detection on our infrastructure
TLS 1.3 encryption in transit
SOC 2 Type II audit (in progress)
Role-based access controls (RBAC)
96-hour breach notification to regulators

Data Protection Officer
Our DPO is available for all data protection enquiries, regulatory requests, and rights exercises.
ChildSafe.dev Inc. — Data Protection Officer333 Sunset Dr, Suite 204, Fort Lauderdale, FL 33301
